Skip to content

Commit 319aba0

Browse files
committed
chore(security): remediate audit findings and lock vulnerable transitive deps
1 parent ae1c3ea commit 319aba0

3 files changed

Lines changed: 714 additions & 970 deletions

File tree

docs/plan/M06-security-and-compliance-hardening.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,3 +40,4 @@ Implement engineering controls for a federal-ready baseline posture.
4040
- 2026-02-11: Added `docs/CONTROL_MAPPING.md` as baseline NIST/FISMA-style evidence mapping artifact.
4141
- 2026-02-11: Added migration `20260211000500_security_audit_and_abuse_events.sql` for append-only `audit_events` trigger capture across key tables and `abuse_events` telemetry storage.
4242
- 2026-02-11: Updated `supabase/functions/submit-comment/index.ts` to record abuse events for CAPTCHA failures/missing tokens, identity-gating failures, and rate-limit thresholds.
43+
- 2026-02-19: Ran dependency remediation for known audit findings; upgraded vulnerable runtime/tooling packages, added `minimatch` override to `10.2.1`, and reduced `npm audit` to moderate-only ESLint-chain advisories while preserving passing lint/typecheck/build.

0 commit comments

Comments
 (0)